Every duty in the AI Act flows from two answers — which role you occupy, and which risk tier your system sits in. Get these two right and everything else follows. Get them wrong and you either over-comply or walk into an enforcement gap.
Provider, deployer, importer or distributor. The same system carries entirely different duties depending on which of these you are.
Prohibited, high-risk, limited-risk (transparency) or minimal. The tier decides how heavy the obligations are — or whether the system is allowed at all.
Most AI Act confusion comes from skipping straight to "what do I have to do" without first fixing "what am I, and what is this system." Those two questions are the whole framework. This is the map — not legal advice, but the structure you need before any of the compliance work makes sense.
The Act (Article 3) assigns duties by role, not by company. The heaviest obligations fall on the provider; the deployer carries a lighter, use-focused set. Importers and distributors sit in between as gatekeepers.
Under Article 25, if you put your own name or trademark on a high-risk system, substantially modify one already on the market, or change its intended purpose so it becomes high-risk, you take on the provider's obligations — the heavy set. Fine-tuning a model and shipping it as your own is the classic way a "we only use it" company wakes up as a provider.
If you are a provider established outside the Union, role classification carries an extra consequence. Before placing a high-risk system on the EU market you must appoint an authorised representative established in the Union (Article 22); the same requirement applies to providers of general-purpose AI models under Article 54 — and that one has been in force since August 2025. Which role you occupy determines whether this obligation is yours at all.
The Act sorts systems into four tiers. Obligations scale with the tier — and the top tier is not a heavy-compliance category, it is a ban.
These have applied since 2 February 2025. If a system does any of the following, no amount of documentation makes it compliant.
A system is high-risk on two routes. Annex I — it is a safety component of a product already regulated under EU harmonisation law (machinery, medical devices, toys, vehicles and so on). Or Annex III — it falls into one of eight listed use areas. The Annex III list is where most software companies discover they are in scope.
Article 6(3) carves out systems that do not pose a significant risk to health, safety or fundamental rights — for example a narrow procedural task, or work that merely improves the result of a completed human activity. But a system that profiles people is always high-risk. If you intend to rely on the exemption, that decision has to be documented and registered, not assumed — and specific carve-outs exist (identity verification, fraud detection, campaign logistics) that are narrower than they sound.
Article 50 is the tier that catches ordinary software — chatbots, generative tools, synthetic media — that is nowhere near high-risk. It is a disclosure regime, and its deadline lands before the high-risk one.
Any product that generates synthetic content for EU users is in scope, regardless of risk classification — and this deadline arrives a full year before the high-risk one. It is the AI Act obligation the broadest set of companies will meet first.
GPAI models run on their own classification, parallel to the system tiers. A provider of a general-purpose model carries baseline obligations — technical documentation, a copyright policy, a training-data summary. A model crosses into the systemic-risk category when the compute used to train it exceeds 1025 FLOPs, which adds model evaluation, adversarial testing, risk mitigation and incident reporting. GPAI obligations, including the Article 54 representative duty for non-EU providers, have applied since August 2025.
Your obligations are the intersection of the role and the tier. The same system produces very different duties depending on where you stand.
| If you are a... | ...and the system is high-risk | ...and it is transparency-tier |
|---|---|---|
| Provider | Risk management, technical docs, quality management, conformity assessment, registration, EU representative if non-EU | Design the disclosure / marking into the system |
| Deployer | Use as instructed, ensure human oversight, monitor, keep logs, inform affected people; run a fundamental-rights impact assessment where required | Inform the people exposed (e.g. label the deepfake, disclose the chatbot) |
| Importer / Distributor | Verify conformity, marking and documentation before making it available | Check the transparency marking is present |
| Tier / obligation | Applies from | Status |
|---|---|---|
| Prohibited practices, AI literacy | 2 February 2025 | In force |
| GPAI model obligations (incl. non-EU representative) | 2 August 2025 | In force |
| Transparency & labelling (Art. 50) | 2 December 2026 | Next up |
| High-risk — Annex III systems | 2 December 2027 | Deferred |
| High-risk — Annex I products | 2 August 2028 | Deferred |
The high-risk dates reflect the 2026 simplification package. The penalty ceiling underneath all of this is real: up to €35 million or 7% of worldwide turnover for prohibited practices, with lower caps for other breaches. Spain has gone further than most member states in building the enforcement architecture — AESIA, its dedicated AI supervisor, has been operational since 2024.
Role and tier are legal determinations of fact, not marketing choices — and the most expensive AI Act mistakes are made by companies that assumed one answer and built on it. Settling them early, with the classification documented, is what turns the AI Act from an open-ended worry into a defined, and deferred, workstream.